Loading...
Loading...
++ASA not sending ACL logging to syslog server ++logs do show in buffered, but not being sent to syslog. Config example: logging enable logging timestamp logging standby logging buffer-size 10000000 logging buffered errors logging trap critical <<<<<<<<<<< Send critical level logs to syslog logging asdm critical logging host management 10.10.10.10 <<<<<<<<<<<<<<<<<<<<<< SYSLOG ++ ACLs with logging enabled: access-list TEST extended permit ip any any log critical ++ACL loggin will show up in buffer. However, ASA will not send these logs to syslog server despite being configured above to send critical traps to syslog server %ASA-2-106100: access-list TEST permitted tcp PRIVATE02/10.200.37.51(53271) -> INSIDE08/10.205.22.250(88) hit-cnt 1 first hit %ASA-2-106100: access-list TEST permitted tcp PRIVATE02/10.250.10.174(57764) -> INSIDE08/10.205.22.250(88) hit-cnt 1 first hit %ASA-2-106100: access-list TEST permitted tcp PRIVATE02/10.200.70.113(50408) -> INSIDE08/10.205.22.250(135) hit-cnt 1 first hit %ASA-2-106100: access-list TEST permitted tcp PRIVATE02/10.200.70.113(50409) -> INSIDE08/10.205.22.250(50135) hit-cnt 1 first h %ASA-2-106100: access-list TEST permitted tcp PRIVATE02/10.200.68.110(51468) -> INSIDE08/10.205.22.250(389) hit-cnt 1 first hit
This issue is first noticed in ASA 9.12.4.53, but it might be hitting other releases as well.
Use an interface other than management
N/A PSIRT Evaluation: The Cisco PSIRT has evaluated this issue and determined it does not meet the criteria for PSIRT ownership or involvement. This issue will be addressed via normal resolution channels. If you believe that there is new information that would cause a change in the severity of this issue, please contact psirt@cisco.com for another evaluation. Additional information on Cisco's security vulnerability policy can be found at the following URL: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.